Description
This module scans for vulnerable N-able N-Central instances affected by CVE-2025-9316 (Unauthenticated Session Bypass) and CVE-2025-11700 (XXE).
The module attempts to exploit CVE-2025-9316 by sending a sessionHello SOAP request to the ServerMMS endpoint with various appliance IDs to obtain an unauthenticated session. If successful, it then tests for CVE-2025-11700 by writing an XXE payload file and triggering it via importServiceTemplateFromFile.
Files of interest that can be read via XXE: - /opt/nable/var/ncsai/etc/ncbackup.conf - /var/opt/n-central/tmp/ncbackup/ncbackup.bin (PostgreSQL dump) - /opt/nable/etc/keystore.bcfks (encrypted keystore) - /opt/nable/etc/masterPassword (keystore password)
Affected versions: N-Central < 2025.4.0.9
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use auxiliary/scanner/http/nable/ncentral_auth_bypass_xxemsf undefined(ncentral_auth_bypass_xxe) > show actions ...actions...msf undefined(ncentral_auth_bypass_xxe) > set ACTION < action-name >msf undefined(ncentral_auth_bypass_xxe) > show options ...show and set options...msf undefined(ncentral_auth_bypass_xxe) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub